<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Monitor CPU, Disk and Ram. in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/Monitor-CPU-Disk-and-Ram/m-p/332699#M5467</link>
    <description>&lt;P&gt;@ fsrodriguez, can you try the following run anywhere search?&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| makeresults
| head 1
| eval yourCPUFieldName=14.2
| gauge yourCPUFieldName 0 10 30 50
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;If the same works you need to replace &lt;CODE&gt;| makeresults&lt;/CODE&gt; with &lt;CODE&gt;your base search&lt;/CODE&gt; to get CPU Value.&lt;BR /&gt;
&lt;CODE&gt;| head 1&lt;/CODE&gt; gets only the latest result for CPU&lt;BR /&gt;
If you want the CPU for multiple hosts you can leverage the &lt;CODE&gt;Trellis Layout&lt;/CODE&gt;, provided your are on Splunk Enterprise version 6.6 or later.&lt;/P&gt;

&lt;P&gt;PS: I have used run anwhere dashboard to use Splunk's _introspection index to get the CPU percent. Also I have used date_hour in the query and also for Trellis split by &lt;CODE&gt;&amp;lt;option name="trellis.splitBy"&amp;gt;date_hour&amp;lt;/option&amp;gt;&lt;/CODE&gt;. You would need to replace your query and also convert from &lt;CODE&gt;date_hour&lt;/CODE&gt; to &lt;CODE&gt;host&lt;/CODE&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;dashboard&amp;gt;
  &amp;lt;label&amp;gt;Radial Gauge for CPU&amp;lt;/label&amp;gt;
  &amp;lt;row&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;title&amp;gt;CPU by date_hour&amp;lt;/title&amp;gt;
      &amp;lt;chart&amp;gt;
        &amp;lt;search&amp;gt;
          &amp;lt;query&amp;gt;index="_introspection" sourcetype="splunk_resource_usage" data.pct_cpu=*
| stats latest(data.pct_cpu) as CPU by date_hour&amp;lt;/query&amp;gt;
          &amp;lt;earliest&amp;gt;-4h@m&amp;lt;/earliest&amp;gt;
          &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
          &amp;lt;sampleRatio&amp;gt;1&amp;lt;/sampleRatio&amp;gt;
        &amp;lt;/search&amp;gt;
        &amp;lt;option name="charting.axisLabelsX.majorLabelStyle.overflowMode"&amp;gt;ellipsisNone&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.axisLabelsX.majorLabelStyle.rotation"&amp;gt;0&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.axisTitleX.visibility"&amp;gt;collapsed&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.axisTitleY.visibility"&amp;gt;collapsed&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.axisTitleY2.visibility"&amp;gt;collapsed&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.axisX.abbreviation"&amp;gt;none&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.axisX.scale"&amp;gt;linear&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.axisY.abbreviation"&amp;gt;none&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.axisY.scale"&amp;gt;linear&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.axisY2.abbreviation"&amp;gt;none&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.axisY2.enabled"&amp;gt;0&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.axisY2.scale"&amp;gt;inherit&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.chart"&amp;gt;radialGauge&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.chart.bubbleMaximumSize"&amp;gt;50&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.chart.bubbleMinimumSize"&amp;gt;10&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.chart.bubbleSizeBy"&amp;gt;area&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.chart.nullValueMode"&amp;gt;gaps&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.chart.rangeValues"&amp;gt;[0,60,85,100]&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.chart.showDataLabels"&amp;gt;none&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.chart.sliceCollapsingThreshold"&amp;gt;0.01&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.chart.stackMode"&amp;gt;default&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.chart.style"&amp;gt;shiny&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.drilldown"&amp;gt;all&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.gaugeColors"&amp;gt;["0x84E900","0xFFE800","0xBF3030"]&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.layout.splitSeries"&amp;gt;0&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.layout.splitSeries.allowIndependentYRanges"&amp;gt;0&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.legend.labelStyle.overflowMode"&amp;gt;ellipsisMiddle&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.legend.mode"&amp;gt;standard&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.legend.placement"&amp;gt;none&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.lineWidth"&amp;gt;2&amp;lt;/option&amp;gt;
        &amp;lt;option name="refresh.display"&amp;gt;progressbar&amp;lt;/option&amp;gt;
        &amp;lt;option name="trellis.enabled"&amp;gt;1&amp;lt;/option&amp;gt;
        &amp;lt;option name="trellis.scales.shared"&amp;gt;1&amp;lt;/option&amp;gt;
        &amp;lt;option name="trellis.size"&amp;gt;small&amp;lt;/option&amp;gt;
        &amp;lt;option name="trellis.splitBy"&amp;gt;date_hour&amp;lt;/option&amp;gt;
      &amp;lt;/chart&amp;gt;
    &amp;lt;/panel&amp;gt;
  &amp;lt;/row&amp;gt;
&amp;lt;/dashboard&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Tue, 29 Sep 2020 17:12:22 GMT</pubDate>
    <dc:creator>niketn</dc:creator>
    <dc:date>2020-09-29T17:12:22Z</dc:date>
    <item>
      <title>Monitor CPU, Disk and Ram.</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Monitor-CPU-Disk-and-Ram/m-p/332696#M5464</link>
      <description>&lt;P&gt;How can I create a radial gauge that would display CPU? and what would be the command for Disk and RAM?&lt;/P&gt;

&lt;P&gt;Thank you in Advance.&lt;/P&gt;</description>
      <pubDate>Sun, 10 Dec 2017 15:37:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Monitor-CPU-Disk-and-Ram/m-p/332696#M5464</guid>
      <dc:creator>fsrodriguez</dc:creator>
      <dc:date>2017-12-10T15:37:15Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor CPU, Disk and Ram.</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Monitor-CPU-Disk-and-Ram/m-p/332697#M5465</link>
      <description>&lt;P&gt;Hi @fsrodriguez,&lt;/P&gt;

&lt;P&gt;Have you checked this link?&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/SplunkCloud/6.6.3/Viz/CreateGauges"&gt;http://docs.splunk.com/Documentation/SplunkCloud/6.6.3/Viz/CreateGauges&lt;/A&gt;&lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/6.6.3/SearchReference/Gauge"&gt;https://docs.splunk.com/Documentation/SplunkCloud/6.6.3/SearchReference/Gauge&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 11 Dec 2017 07:34:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Monitor-CPU-Disk-and-Ram/m-p/332697#M5465</guid>
      <dc:creator>kamlesh_vaghela</dc:creator>
      <dc:date>2017-12-11T07:34:31Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor CPU, Disk and Ram.</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Monitor-CPU-Disk-and-Ram/m-p/332698#M5466</link>
      <description>&lt;P&gt;The links above detail how to chart the data if you have it, but Is your question:&lt;BR /&gt;
&lt;STRONG&gt;How do I get CPU/Disk/Ram metrics into Splunk?&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;If so, can you detail which operating systems you are interested in monitoring?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Dec 2017 08:42:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Monitor-CPU-Disk-and-Ram/m-p/332698#M5466</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2017-12-11T08:42:20Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor CPU, Disk and Ram.</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Monitor-CPU-Disk-and-Ram/m-p/332699#M5467</link>
      <description>&lt;P&gt;@ fsrodriguez, can you try the following run anywhere search?&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;| makeresults
| head 1
| eval yourCPUFieldName=14.2
| gauge yourCPUFieldName 0 10 30 50
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;If the same works you need to replace &lt;CODE&gt;| makeresults&lt;/CODE&gt; with &lt;CODE&gt;your base search&lt;/CODE&gt; to get CPU Value.&lt;BR /&gt;
&lt;CODE&gt;| head 1&lt;/CODE&gt; gets only the latest result for CPU&lt;BR /&gt;
If you want the CPU for multiple hosts you can leverage the &lt;CODE&gt;Trellis Layout&lt;/CODE&gt;, provided your are on Splunk Enterprise version 6.6 or later.&lt;/P&gt;

&lt;P&gt;PS: I have used run anwhere dashboard to use Splunk's _introspection index to get the CPU percent. Also I have used date_hour in the query and also for Trellis split by &lt;CODE&gt;&amp;lt;option name="trellis.splitBy"&amp;gt;date_hour&amp;lt;/option&amp;gt;&lt;/CODE&gt;. You would need to replace your query and also convert from &lt;CODE&gt;date_hour&lt;/CODE&gt; to &lt;CODE&gt;host&lt;/CODE&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;lt;dashboard&amp;gt;
  &amp;lt;label&amp;gt;Radial Gauge for CPU&amp;lt;/label&amp;gt;
  &amp;lt;row&amp;gt;
    &amp;lt;panel&amp;gt;
      &amp;lt;title&amp;gt;CPU by date_hour&amp;lt;/title&amp;gt;
      &amp;lt;chart&amp;gt;
        &amp;lt;search&amp;gt;
          &amp;lt;query&amp;gt;index="_introspection" sourcetype="splunk_resource_usage" data.pct_cpu=*
| stats latest(data.pct_cpu) as CPU by date_hour&amp;lt;/query&amp;gt;
          &amp;lt;earliest&amp;gt;-4h@m&amp;lt;/earliest&amp;gt;
          &amp;lt;latest&amp;gt;now&amp;lt;/latest&amp;gt;
          &amp;lt;sampleRatio&amp;gt;1&amp;lt;/sampleRatio&amp;gt;
        &amp;lt;/search&amp;gt;
        &amp;lt;option name="charting.axisLabelsX.majorLabelStyle.overflowMode"&amp;gt;ellipsisNone&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.axisLabelsX.majorLabelStyle.rotation"&amp;gt;0&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.axisTitleX.visibility"&amp;gt;collapsed&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.axisTitleY.visibility"&amp;gt;collapsed&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.axisTitleY2.visibility"&amp;gt;collapsed&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.axisX.abbreviation"&amp;gt;none&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.axisX.scale"&amp;gt;linear&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.axisY.abbreviation"&amp;gt;none&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.axisY.scale"&amp;gt;linear&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.axisY2.abbreviation"&amp;gt;none&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.axisY2.enabled"&amp;gt;0&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.axisY2.scale"&amp;gt;inherit&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.chart"&amp;gt;radialGauge&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.chart.bubbleMaximumSize"&amp;gt;50&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.chart.bubbleMinimumSize"&amp;gt;10&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.chart.bubbleSizeBy"&amp;gt;area&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.chart.nullValueMode"&amp;gt;gaps&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.chart.rangeValues"&amp;gt;[0,60,85,100]&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.chart.showDataLabels"&amp;gt;none&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.chart.sliceCollapsingThreshold"&amp;gt;0.01&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.chart.stackMode"&amp;gt;default&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.chart.style"&amp;gt;shiny&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.drilldown"&amp;gt;all&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.gaugeColors"&amp;gt;["0x84E900","0xFFE800","0xBF3030"]&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.layout.splitSeries"&amp;gt;0&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.layout.splitSeries.allowIndependentYRanges"&amp;gt;0&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.legend.labelStyle.overflowMode"&amp;gt;ellipsisMiddle&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.legend.mode"&amp;gt;standard&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.legend.placement"&amp;gt;none&amp;lt;/option&amp;gt;
        &amp;lt;option name="charting.lineWidth"&amp;gt;2&amp;lt;/option&amp;gt;
        &amp;lt;option name="refresh.display"&amp;gt;progressbar&amp;lt;/option&amp;gt;
        &amp;lt;option name="trellis.enabled"&amp;gt;1&amp;lt;/option&amp;gt;
        &amp;lt;option name="trellis.scales.shared"&amp;gt;1&amp;lt;/option&amp;gt;
        &amp;lt;option name="trellis.size"&amp;gt;small&amp;lt;/option&amp;gt;
        &amp;lt;option name="trellis.splitBy"&amp;gt;date_hour&amp;lt;/option&amp;gt;
      &amp;lt;/chart&amp;gt;
    &amp;lt;/panel&amp;gt;
  &amp;lt;/row&amp;gt;
&amp;lt;/dashboard&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 29 Sep 2020 17:12:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Monitor-CPU-Disk-and-Ram/m-p/332699#M5467</guid>
      <dc:creator>niketn</dc:creator>
      <dc:date>2020-09-29T17:12:22Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor CPU, Disk and Ram.</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Monitor-CPU-Disk-and-Ram/m-p/332700#M5468</link>
      <description>&lt;P&gt;I'm trying to pull it from an Amazon Linux AMI.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Dec 2017 13:22:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Monitor-CPU-Disk-and-Ram/m-p/332700#M5468</guid>
      <dc:creator>fsrodriguez</dc:creator>
      <dc:date>2017-12-11T13:22:57Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor CPU, Disk and Ram.</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Monitor-CPU-Disk-and-Ram/m-p/332701#M5469</link>
      <description>&lt;P&gt;Yes I've seen that documentation, thank you. I know how to create it but I don't know how to pull the data values I need. CPU RAM and MEM.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Dec 2017 13:50:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Monitor-CPU-Disk-and-Ram/m-p/332701#M5469</guid>
      <dc:creator>fsrodriguez</dc:creator>
      <dc:date>2017-12-11T13:50:29Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor CPU, Disk and Ram.</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Monitor-CPU-Disk-and-Ram/m-p/332702#M5470</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/78844"&gt;@fsrodriguez&lt;/a&gt;&lt;/P&gt;

&lt;P&gt;please download &lt;A href="https://splunkbase.splunk.com/app/833/#/details" target="_blank"&gt;https://splunkbase.splunk.com/app/833/#/details&lt;/A&gt;.&lt;/P&gt;

&lt;P&gt;1) Deploy this Splunk_TA_nix to the servers were you have to monitor&lt;BR /&gt;
2) Enable CPU,RAM and DISK script&lt;BR /&gt;
3) restart the server. &lt;BR /&gt;
4) you will get the data under os index.&lt;/P&gt;

&lt;P&gt;or&lt;/P&gt;

&lt;P&gt;Try with NMON . It will pull you all necessary metrics from linux hosts ( except HPUX os)&lt;BR /&gt;
&lt;A href="https://splunkbase.splunk.com/app/3248/" target="_blank"&gt;https://splunkbase.splunk.com/app/3248/&lt;/A&gt; - TA-nmon - need to be install/deployed on UF / hosts&lt;BR /&gt;
&lt;A href="https://splunkbase.splunk.com/app/1753/" target="_blank"&gt;https://splunkbase.splunk.com/app/1753/&lt;/A&gt; - NMON APP - need to be installed or deployed on SH (But look for data model settings)&lt;/P&gt;

&lt;P&gt;I hope this helps you.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 17:11:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Monitor-CPU-Disk-and-Ram/m-p/332702#M5470</guid>
      <dc:creator>sbbadri</dc:creator>
      <dc:date>2020-09-29T17:11:06Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor CPU, Disk and Ram.</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Monitor-CPU-Disk-and-Ram/m-p/332703#M5471</link>
      <description>&lt;P&gt;I already had Splunk_TA_nix Installed. Thank you so much! &lt;/P&gt;

&lt;P&gt;This is all I had to do:&lt;BR /&gt;
    host="app-1" source="cpu" | gauge cpu_load_percent 25 50 65 75 85 95 100&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 17:11:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Monitor-CPU-Disk-and-Ram/m-p/332703#M5471</guid>
      <dc:creator>fsrodriguez</dc:creator>
      <dc:date>2020-09-29T17:11:15Z</dc:date>
    </item>
  </channel>
</rss>

